Tycoon, also tracked as RedRum, Grinch, and in some reporting alongside Thanos-linked variants, emerged as a manually deployed ransomware threat against enterprise environments on both Windows and Linux. Operators were reported to gain access through vulnerable or exposed RDP services, then encrypt files with AES-256-GCM while protecting encryption keys with RSA-1024. The malware appended extensions including .redrum, .grinch, .thanos, .eruption, and .magneto, and dropped a ransom note named decryption.txt using contact addresses such as moncler@tutamail.com and moncler@cock.li.
Reporting also tied the activity to broader Thanos ransomware development, a .NET-based RaaS ecosystem that enabled extensive customization, persistence, anti-analysis, and defense-evasion features across multiple later variants. The malware was described as deleting shadow copies and disabling recovery and firewall protections while avoiding some system files and directories to keep infected systems operational. Historical tracking indicates some early Hakbit-identified and RedRum samples could be decrypted, including with an Emsisoft decryptor, while later corrected Thanos-derived variants adopted stronger RSA-based encryption that generally prevented recovery without the attackers' private key.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
RedRum ransomware activity is placed in early December 2019. The family targeted enterprise environments on Windows and Linux, using manually deployed payloads after access through exposed or vulnerable RDP servers.
A later Thanos variant using the .cyber extension was observed. It contacted victims via cyber@outlookpro.net, queried external IPs through icanhazip.com, disabled Task Manager via the registry, and downloaded PsExec from Sysinternals.
A .ravack variant was observed and described as a renamed copy of the earlier .abarcy variant. The campaign was distributed through a trojanized Movavi.Video.Editor.Plus.20.2.0.exe installer.
A variant self-identifying as Corona ransomware was observed and claimed to use RSA4096 and AES-256. It used the contact email recoba90@protonmail.com and a specified Bitcoin wallet for ransom payments.
A Hakbit/Thanos-linked variant using the .abarcy extension was observed, with victim contact via the Discord tag Abarcy#2996. The source presents it as part of the evolving Hakbit-to-Thanos lineage.
The Hakbit ransomware family was active by November 2019, with the source stating its activity peaked in early November. Early samples commonly used the .crypted extension and ransom notes tied to hakbit@protonmail.com.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 82 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
blogs.blackberry.com
Open sourceid-ransomware.blogspot.com
Open sourceid-ransomware.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.